Hackers Exploit QNAP Devices: Active Exploitation of QNAP VioStor NVR Vulnerability Discovered

The increasing reliance on network-attached storage (NAS) devices has made them an attractive target for hackers. QNAP devices, in particular, have become a favored choice for attackers due to their susceptibility to known vulnerabilities and misconfigurations. In this article, we delve into the latest findings by cybersecurity researchers at Akamai, who have discovered active exploitation of the QNAP VioStor Network Video Recorder (NVR) vulnerability, exposing users to the notorious ‘Mirai’ malware.

Exploitation of QNAP VioStor NVR Vulnerability

During their research, the cybersecurity experts at Akamai uncovered that hackers have been actively taking advantage of the QNAP VioStor NVR vulnerability, which has been assigned the CVE-2023-47565 tracking number. This vulnerability has been marked as a ‘High’ severity flaw, with a CVSS v3 score of 8.0, emphasizing the significant risk it poses to users.

By utilizing an OS command injection technique, authorized attackers exploit this vulnerability by initiating a POST request to the management interface. By leveraging the device’s default credentials, they gain unauthorized access to the system, providing an entry point for malicious activities. This exploitation technique allows the attacker to deploy the notorious ‘Mirai’ malware, further compromising the device and potentially enabling it to become part of a botnet.

Recommendations by QNAP

In response to the active exploitation of the QNAP VioStor NVR vulnerability, QNAP has issued recommendations to mitigate the risk for its users. It is essential for users to upgrade their VioStor firmware, particularly on unsupported devices, to ensure they have the latest security patches. Additionally, changing default passwords offers an additional layer of protection against unauthorized access, thwarting potential hackers.

Discovery of Undisclosed Patched Issue

During the course of the InfectedSlurs campaign, the Akamai researchers discovered an undisclosed patched issue. While details remain undisclosed, this discovery highlights the continuous efforts by hackers to exploit vulnerabilities in QNAP devices, necessitating constant vigilance by both users and manufacturers.

SIRT Identifies QNAP VioStor NVR Devices as Targets

The Security Incident Response Team (SIRT) has identified QNAP VioStor NVR devices as primary targets for exploitation. This underscores the importance of taking immediate action to address the known vulnerabilities and weaknesses in the device’s systems to prevent unauthorized access and subsequent compromise.

Confirmation of Targeted Retired VioStor Versions

Following collaboration with US-CERT and QNAP, it has been confirmed that retired VioStor versions, specifically those of 5.0.0 or earlier, are the primary targets of active exploitation. Attackers exploit a remote code execution vulnerability through a POST request to /cgi-bin/server/server.cgi. It is crucial for users utilizing these retired versions to take immediate action to mitigate the risk and protect their QNAP VioStor NVR devices.

Highlighting the Importance of Secure IoT Practices

The discovery of ongoing exploitation of QNAP devices highlights the significance of implementing secure Internet of Things (IoT) practices. Default credentials and outdated network systems create opportunities for botnet infections and expose users to new vulnerabilities. The need for improved IoT practices is evident in the case of legacy systems, which can become breeding grounds for malicious activities. Utilizing strong, unique passwords and regularly updating firmware can significantly mitigate such risks.

The active exploitation of the QNAP VioStor NVR vulnerability serves as a wake-up call for both QNAP device users and manufacturers. Proactive measures, such as promptly upgrading firmware and changing default passwords, can go a long way in safeguarding against unauthorized access and subsequent compromise. Continuous collaboration between researchers, manufacturers, and cybersecurity organizations is crucial in combating the evolving threats posed by hackers targeting IoT devices. By remaining vigilant and adhering to the best security practices, users can ensure a safer and more secure digital environment.

Explore more

Review of Linux Mint 22.2 Zara

Introduction to Linux Mint 22.2 Zara Review Imagine a world where an operating system combines the ease of use of mainstream platforms with the freedom and customization of open-source software, all while maintaining rock-solid stability. This is the promise of Linux Mint, a distribution that has long been a favorite for those seeking an accessible yet powerful alternative. The purpose

Trend Analysis: AI and ML Hiring Surge

Introduction In a striking revelation about the current state of India’s white-collar job market, hiring for Artificial Intelligence (AI) and Machine Learning (ML) roles has skyrocketed by an impressive 54 percent year-on-year as of August this year, standing in sharp contrast to the modest 3 percent overall growth in hiring across professional sectors. This surge underscores the transformative power of

Why Is Asian WealthTech Funding Plummeting in Q2 2025?

In a striking turn of events, the Asian WealthTech sector has experienced a dramatic decline in funding during the second quarter of this year, raising eyebrows among industry watchers and stakeholders alike. Once a hotbed for investment and innovation, this niche of financial technology is now grappling with a steep drop in investor confidence, reflecting broader economic uncertainties across the

Trend Analysis: AI Skills for Young Engineers

In an era where artificial intelligence is revolutionizing every corner of the tech industry, a staggering statistic emerges: over 60% of engineering roles now require some level of AI proficiency to remain competitive in major firms. This rapid integration of AI is not just a fleeting trend but a fundamental shift that is reshaping career trajectories for young engineers. As

How Does SOCMINT Turn Digital Noise into Actionable Insights?

I’m thrilled to sit down with Dominic Jainy, a seasoned IT professional whose deep expertise in artificial intelligence, machine learning, and blockchain uniquely positions him to shed light on the evolving world of Social Media Intelligence, or SOCMINT. With his finger on the pulse of cutting-edge technology, Dominic has a keen interest in how digital tools and data-driven insights are